nerdexam
(ISC)2

HCISPP · Question #265

You are provided a network vulnerability scan of the hospital network. There are numerous critical unpatched vulnerabilities on many of the devices. You work with the person who runs the centralized…

The correct answer is C. Exclude medical devices from the updates. Medical devices (e.g., infusion pumps, ventilators, imaging systems) are FDA-regulated and operate under strict vendor certifications. Applying unauthorized or automated patches to medical devices can void FDA clearance, break proprietary firmware, disrupt life-critical…

Information Technologies in Healthcare

Question

You are provided a network vulnerability scan of the hospital network. There are numerous critical unpatched vulnerabilities on many of the devices. You work with the person who runs the centralized vulnerability patching team to develop a remediation approach that includes automated security patching of systems. Which of these steps would you take next?

Options

  • AContact system owners to advise them of the updates.
  • BSchedule the remediation patching after clinical hours.
  • CExclude medical devices from the updates.
  • DQuarantine vulnerable systems per policy.

How the community answered

(33 responses)
  • A
    12% (4)
  • B
    6% (2)
  • C
    79% (26)
  • D
    3% (1)

Explanation

Medical devices (e.g., infusion pumps, ventilators, imaging systems) are FDA-regulated and operate under strict vendor certifications. Applying unauthorized or automated patches to medical devices can void FDA clearance, break proprietary firmware, disrupt life-critical functionality, or violate regulatory requirements. Before medical devices can be patched, the device manufacturer must approve and validate the patch. Therefore, they must be excluded from automated patching programs and handled through a separate, vendor-coordinated process. Automatically patching medical devices without manufacturer authorization poses a direct patient safety risk, making their exclusion the critical first step.

Topics

#Medical Device Security#Vulnerability Management#Security Patching#Healthcare IT Operations

Community Discussion

No community discussion yet for this question.

Full HCISPP Practice